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Trojan Horses strike 
gain! 


A new Trojan War broke out 
recently, this time the battle- 
field is not ‘the wind-swept 
plain’ but the Internet. This 
time he victims are the PCs 
of innocent users. Fortu- 
nately, a good defence 
against the nefarious 
invader may also be found 
on the same Internet. 
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Detar es das 


Save war dark.. 


NetBus und NetBuster 


Eurosubmit MiniB anners 








Es war schon immer ein Traum der Menschheit, 
andere Computer zu überwachen und zu 
steuern. Auf dem Internet kursieren deshalb 
diverse Programme, welche dem Benutzer eine 
solche Überwachung ermöglichen. Zu diesem 
Zwecke wird auf einem Zielrechner (= 
Rechner, der ausspioniert werden soll) ein 
Serverprogramm installiert, welches es dem 
Benutzer ermöglicht, mit dem dazugehörenden 
Clentprogramm gewisse Aktionen (z.B. 
Formatieren der Festplatte) zu tätigen. Das 
Serverprogramm aktiviert sich bei jedem Start 
des Betriebssystems und kann von den 
Anwendern des dazugehörenden 
Clientprogrammes dazu benutzt werden, die von NetBus aktivierten Sicherheitshicken (z.B. offener Port) zu 
missbrauchen. 


Server admin | Host namesP: [195.162.163.156 =| Port:fi2345 

|| Open CD-ROM ] [ inintervat: [0 About | adap | Cancet_| 
Show image | Function delay: b _Memo | Deir | e sam | 
Swap mouse | Port Redirect | App Redirect | Server setup | 
Start program | Play sound | þb [p Control mouse | 
Msg manager | Exit Vindovwes | Mouse pos | Go to URL | 
Screendump | Send text | Listen | Key manager | 
Get info | Active wnds | Sound system | File manager | 


® NetBus 1.70. by cf 


Connected to 195.162.163.156 (ver 1.70) 





Zwei bekannte Programme, welche das Monitoring über das Internet sprich TCP/IP-Protokoll erlauben, sind Back 
Orifice und NetBus. Im Grunde genommen handelt es sich bei diesen Programmen um Trojanische Pferde. Als 
Trojanische Pferde werden Programme bezeichnet, die vorgeben, eine gewisse Aufgabe zu erfüllen, aber in 
Wirklichkeit eine andere Funktion ausüben. Das NetBus Serverprogramm PATCH. EXE wird beispielsweise in ein 
Wrirtsprosramm (z.B. Weihnachtserisse als EXE-File) integriert und beim Aufstarten desjenigen aktiviert. Jedes Mal 
wenn sich der befallene Computer (in diesem Fall Server) am Internet anmeldet, steht er fiir Anoriffe bereit. 
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Have you ever heard of Netbus or 
Back Orifice? If not, then you have 
been spared the disasters brought 
asbout by two new viruses dissemi- 
nated via the Internet. These so-called 
Trojan Horses are worse than almost 
any other virus known so far, because 
the sender gets control of all ‘infected’ 
computers. In practice, ‘control’ 
includes remotely operating your key- 
board or mouse, activating the CD- 


ROM drive, or placing a banner on 
your screen. Effectively, the PC gets a 
kind of invisible remote contro! which 
IS Operated via the Internet. 

As soon as an infected computer is 
connected to the Internet, the sender 
of the Trojan Horse viruses may con- 
trol all the PC functions that are within 
his power. Of course, this is no longer 
possible as soon as the Internet con- 
nection is terminated. 


Thesender of these viruses also gets 
full control over all files stored on the 
infected PC, which ts left extremely 
vulnerable to electronic vandalism of 
the worst sort: gone are your personal 
notes and other confidential informa- 
tion like credit card numbers — all of it 
may be thrown on the street for all 
sorts of unauthorized use. It will be 
your worst nightmare! 

The typical behaviour of these Tro- 
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BackWork 





+31-76-5602742 


General Download 
News 
Download Download Backvwork2 from : 


FAQ & Docs 
BackWork ? 
Info about BO 
The makers 
BO links 


Nederlands 


bY Best viewed in 800x600 vrith Netscape 4.0x 


Internet Provider xs4all (www. xs4all nl} 








Pine Internet Security Digest (www.pine.nl 





If you want to be informed about updates and other major changes to 
BackWork fill in this form. 
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jan Horses bears a great resemblance to 
the trick used by the ancient Greeks to 
Invade and conquer the city of Troy 
after years of unsuccessful besieging. 
The virus is usually spread by means 
of anice little program, or a dressed-up 
email message which, when opened 
on the receiving PC, infects the system 
by installing a small server program. 
Next, this server utility makes itself 
Invisible and immediately starts its 
destructive work as soon as the PC is 
linked to the Internet. 

The good news is that the virus 
infection may be neutralized by means 
of a disinfectant program, Framework, 
which may be downloaded free of 
charge at www.framework.nl. On detect- 
ing one of the 45 known Trojan Horses, 
Framework stalls it, and prompts the 
user to eliminate it. If the answer is 
affirmative (what else can we answer, 
we wonder?), then the horse Is killed 
In action. 
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